Rejuvenate IT Logo

Microsoft fixed 570 security holes in a single month – nearly triple its old record

Microsoft’s July update fixed 570 security flaws – close to three times its previous record for a single month. Around 60 were rated critical, and of three flaws that were public before the patch arrived, two were already being used in attacks, according to Krebs on Security.

The list includes a flaw in Microsoft’s Copilot assistant rated 9.6 out of 10, a way past BitLocker disk encryption, and problems in SharePoint and in the service many businesses use to sign in to other systems with their Microsoft account. Roughly 250 of the 570 were flaws that let an attacker who already has a foothold give themselves more power on the machine.

Microsoft’s explanation for the jump is worth reading twice. Its executive vice president Pavan Davuluri put the increase down to artificial intelligence making it possible to find more issues, faster, across more code. If that holds, months like this one stop being remarkable.

Who this affects

Everybody running Windows, which is very nearly everybody. But the practical impact lands hardest on businesses where patching is somebody’s good intention rather than somebody’s job.

A hundred and eighty patches a month can be absorbed informally. Five hundred and seventy cannot. When the volume triples, the gap between “we keep things up to date” and “we have a process that proves it” stops being a technicality – and the flaws already under attack are in that pile with everything else, indistinguishable unless somebody is sorting by risk rather than working down a list.

What to do

  • Take a backup before a month like this one. Krebs’s own advice, and it is sound: large updates occasionally break things, and you want a way back.
  • Do not rush, but do not drift either. Waiting a few days for problems to surface is sensible. Waiting a few months is how businesses end up on a list of flaws under active attack.
  • Sort by what is actually being exploited. Two of these were in use before the patch existed. Those go first, ahead of the other 568.
  • Check the machines nobody logs into. The server in the cupboard, the reception PC, the laptop of the person who left. They get patched when somebody restarts them, and nobody does.
  • Know who is doing this and when. If the honest answer is “Windows does it automatically, I think”, that is the thing to fix – before the volume doubles again.

The boring answer is the right one

Patching is not interesting and it never will be, which is exactly why it slips. The businesses that come through months like July are not the ones with the cleverest kit – they are the ones where somebody knows which machines exist, checks that updates landed, and chases the three that did not.

That is ordinary monthly work for us rather than a project. Our IT support keeps machines current and proves it, and vulnerability scanning looks from the outside for anything missed – more than 150 automated checks every hour, so a machine that quietly stopped updating shows up as a job rather than a headline.

Call us on 01202 237 273 or book a call.